
Digital forensics and Cybersecurity Course
Master the technical and legal skills that define professional digital forensics and cybersecurity investigation. This course takes you from core evidence principles to advanced memory, network, and cloud forensics. You will graduate ready to investigate real incidents, testify as an expert, and protect organizations from evolving threats.
What your team will master:
You will build a complete forensic skill set covering evidence acquisition, disk and file system analysis, memory forensics, and network traffic investigation. You will learn how to set up a compliant forensic lab, maintain chain of custody, and produce court-admissible evidence. The course covers incident response workflows, threat hunting, malware analysis, and cloud forensics. You will also study mobile and IoT device investigation, threat intelligence integration, and penetration testing fundamentals. By the end, you will know how to write professional forensic reports and perform effectively as an expert witness.
How your team learns in practice Digital forensics and Cybersecurity Course
How your team practices Digital forensics and Cybersecurity Course
Professionals from these companies study at Dedika









Course Content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Digital Forensics
Foundations of Digital Forensics
Lesson 1 • Legal and Ethical Foundations
Covers admissibility standards, chain of custody, and investigator ethics. Connects legal requirements to every subsequent technical procedure.
Lesson 2 • Types of Digital Evidence
Catalogs volatile, non-volatile, and network-based evidence categories. Prepares students to recognize evidence types before learning acquisition techniques.
Lesson 3 • The Forensic Investigation Process
Presents the standard phases: identification, preservation, collection, analysis, and reporting. Students map each phase to real-world investigative tasks.
Lesson 4 • Introduction to Digital Forensics
Defines digital forensics, its scope, and its role in legal and corporate investigations. Grounds students in the discipline before any technical content.
Lesson 5 • Forensic Lab Setup and Standards
Describes hardware, software, and procedural requirements for a compliant forensic lab. Students understand the environment in which all subsequent work occurs.
Chapter 2HideHide detailsSee detailsCybersecurity Fundamentals for Investigators
Cybersecurity Fundamentals for Investigators
Lesson 1 • Security Controls and Their Forensic Relevance
Reviews firewalls, IDS/IPS, SIEM, and access controls as sources of forensic artifacts. Students learn to query security tools for evidence.
Lesson 2 • Cryptography Essentials
Introduces hashing, symmetric and asymmetric encryption, and PKI as they apply to evidence integrity and encrypted data challenges.
Lesson 3 • Networking Concepts for Forensics
Covers TCP/IP, DNS, DHCP, and packet structure as they relate to evidence interpretation. Provides the network literacy required for later traffic analysis chapters.
Lesson 4 • Operating System Internals
Examines Windows, Linux, and macOS artifacts relevant to forensic analysis. Students learn where the OS stores evidence before performing disk analysis.
Lesson 5 • Threat Actors and Attack Taxonomy
Classifies threat actors, motives, and common attack categories to frame investigative hypotheses. Directly supports the incident response chapters that follow.
Chapter 3HideHide detailsSee detailsEvidence Acquisition and Preservation
Evidence Acquisition and Preservation
Lesson 1 • Hashing and Evidence Integrity
Demonstrates MD5, SHA-1, and SHA-256 verification workflows to prove evidence has not been altered. Ties integrity verification to chain of custody documentation.
Lesson 2 • Live System and Volatile Data Capture
Addresses RAM capture, running process lists, and network state collection on live systems. Prepares students for memory forensics in the next chapter.
Lesson 3 • Disk Imaging Principles and Tools
Covers bit-for-bit imaging, image formats, and leading acquisition tools. Establishes the technical baseline for all subsequent disk analysis work.
Lesson 4 • Mobile Device Acquisition
Covers logical, file system, and physical extraction methods for smartphones and tablets. Addresses the unique challenges of mobile evidence preservation.
Lesson 5 • Network Traffic Capture
Teaches packet capture placement, tool configuration, and evidence preservation for network data. Connects to network forensics analysis covered later.
Chapter 4HideHide detailsSee detailsDisk and File System Forensics
Disk and File System Forensics
Lesson 1 • Partition and Volume Analysis
Analyzes MBR, GPT, and volume shadow copies to find hidden or deleted partitions. Expands the scope of disk examination beyond the primary partition.
Lesson 2 • File Recovery and Data Carving
Covers deleted file recovery, slack space analysis, and signature-based carving. Students apply these techniques to recover evidence from unallocated space.
Lesson 3 • File System Structures
Examines FAT, NTFS, ext4, and APFS structures to locate evidence at the sector level. Understanding structure is prerequisite to recovery and carving techniques.
Lesson 4 • Metadata and Timestamp Analysis
Extracts and interprets file metadata, EXIF data, and MACB timestamps to build event timelines. Directly feeds the timeline analysis section of this chapter.
Lesson 5 • Timeline Construction from Disk Artifacts
Aggregates timestamps from multiple disk sources into a unified event timeline. Students produce a timeline that supports investigative conclusions.
Chapter 5HideHide detailsSee detailsMemory and Malware Forensics
Memory and Malware Forensics
Lesson 1 • Process and DLL Analysis
Identifies malicious processes, injected DLLs, and hollowed processes within memory images. Core technique for detecting fileless and in-memory malware.
Lesson 2 • Malware Identification and Classification
Applies static and behavioral indicators to classify malware families found in memory. Prepares students for deeper malware analysis in the next section.
Lesson 3 • Network Artifacts in Memory
Extracts active connections, listening ports, and socket structures from RAM. Connects memory findings to network forensics evidence for corroboration.
Lesson 4 • Memory Structure and Acquisition Review
Reviews RAM layout, virtual address spaces, and acquisition methods before analysis begins. Ensures students can work with memory images from the previous chapter.
Lesson 5 • Malware Analysis Techniques
Introduces static disassembly, dynamic sandbox execution, and code unpacking for malware samples. Students produce an analysis report suitable for incident response.
Chapter 6HideHide detailsSee detailsNetwork Forensics and Log Analysis
Network Forensics and Log Analysis
Lesson 1 • Packet Capture Analysis
Teaches deep packet inspection, stream reassembly, and protocol decoding using capture files. Builds on acquisition skills to produce actionable network evidence.
Lesson 2 • Flow Data and NetFlow Analysis
Uses flow records to identify anomalous traffic patterns and data exfiltration without full packet data. Complements full packet analysis for high-volume environments.
Lesson 3 • Intrusion Detection and Attribution
Applies network evidence to confirm intrusion, identify lateral movement, and support attribution. Culminates network forensics skills into a complete investigation narrative.
Lesson 4 • System and Security Log Correlation
Correlates Windows event logs, syslog, and firewall logs to build a cross-source attack timeline. Integrates with SIEM concepts introduced in Chapter 2.
Lesson 5 • Web and Application Log Analysis
Parses web server, application, and proxy logs to reconstruct attacker web activity. Directly supports investigation of web-based attack vectors.
Chapter 7HideHide detailsSee detailsIncident Response and Threat Hunting
Incident Response and Threat Hunting
Lesson 1 • Incident Response Lifecycle
Maps the preparation, detection, containment, eradication, recovery, and lessons-learned phases to forensic tasks. Provides the operational framework for this chapter.
Lesson 2 • Post-Incident Analysis and Lessons Learned
Structures root cause analysis, gap identification, and control improvement after an incident. Closes the IR lifecycle and feeds improvements back into security posture.
Lesson 3 • Containment and Eradication Strategies
Examines network isolation, account disabling, and malware removal while preserving evidence. Balances operational recovery needs with forensic integrity requirements.
Lesson 4 • Triage and Rapid Assessment
Covers rapid host triage, artifact prioritization, and scope determination under time pressure. Enables investigators to make fast, evidence-based containment decisions.
Lesson 5 • Threat Hunting Fundamentals
Introduces hypothesis-driven hunting using TTPs, threat intelligence, and behavioral analytics. Extends reactive IR skills into proactive detection capability.
Chapter 8HideHide detailsSee detailsForensic Reporting and Expert Testimony
Forensic Reporting and Expert Testimony
Lesson 1 • Writing for Technical and Legal Audiences
Adapts forensic findings for attorneys, executives, and technical peers without sacrificing accuracy. Develops the communication versatility investigators need in practice.
Lesson 2 • Expert Witness Preparation
Prepares students for deposition, direct examination, and cross-examination as a forensic expert. Addresses the unique pressures of testifying in adversarial proceedings.
Lesson 3 • Case File Management and Archiving
Establishes procedures for organizing, securing, and archiving complete case files for future reference. Ensures long-term defensibility of investigative work product.
Lesson 4 • Forensic Report Structure and Standards
Defines required report sections, objectivity standards, and documentation best practices. Establishes the reporting framework used throughout the final project.
Lesson 5 • Evidence Presentation and Visualization
Covers timeline charts, network diagrams, and artifact maps that make complex evidence accessible. Directly supports both written reports and courtroom presentations.
Your valid completion certificate
This course is for you:
IT Administrator: wants to formalize incident handling skills with investigative rigor.
Career Changer: brings analytical thinking and is ready to enter cybersecurity professionally.
Security Analyst: needs deeper forensic methodology to support escalated threat investigations.
Law Enforcement Officer: handles digital evidence and wants stronger technical examination skills.
Compliance Professional: must understand how digital investigations protect organizational liability.
Computer Science Graduate: seeks a specialized, career-defining edge in the security job market.
Related Courses
FAQ
Who is Dedika?
Is the certificate valid in Canada?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course



















